CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

UNC2891 ATM Fraud Campaign Targets Indonesian Banks

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

UNC2891, a threat group, conducted a multi-year ATM fraud campaign against two Indonesian banks, involving Raspberry Pi-based ATM infiltration, money mule recruitment, and sophisticated malware. The group executed three attacks between 2022 and 2024, using the STEELCORGI packing tool and advanced tools like CAKETAP rootkit to bypass ATM verification. The campaign included extensive money extraction networks and anti-forensic techniques to evade detection. The group compromised over 30 systems at Bank A in February 2022, demonstrating persistent access and sophisticated attack methods.

Timeline

  1. 20.11.2025 18:00 1 articles · 23h ago

    UNC2891 Conducts Multi-Year ATM Fraud Campaign Against Indonesian Banks

    UNC2891 executed three attacks between 2022 and 2024 against two Indonesian banks, using sophisticated malware and money mule networks. The group employed advanced techniques like CAKETAP rootkit for PIN bypass and maintained persistence with custom backdoors. The campaign involved extensive money extraction networks and anti-forensic measures to evade detection.

    Show sources

Information Snippets